EPISODE · Mar 9, 2021 · 42 MIN
Liran Tal — Cloud native application security, what’s a developer to do?
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Cloud-native development gives engineers control over more of the stack, but it also gives them more security decisions to get wrong. Liran Tal, an open-source contributor and developer advocate, joins Chris and Robert to explore that expanding responsibility. They define cloud-native applications, examine containers and infrastructure as code, and discuss how security ownership changes when developers choose runtimes, dependencies, and deployment configurations. Liran explains why vulnerability severity alone is a poor guide to remediation and why usable feedback matters more than another long list of findings. The conversation also covers practical container-building mistakes, production behavior, and the value of asking what could go wrong while writing code. His advice centers on awareness, helpful defaults, and tools that support developers.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Liran Tal:→ Liran Tal’s websiteMentioned in this episode:→ Node.js→ Docker→ Kubernetes→ SnykFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Cloud-native application security with Liran Tal05:25 Defining cloud-native development07:26 What is changing in the cloud-native stack09:36 Who owns application and infrastructure security13:32 Security in the local developer workflow15:15 Threats in cloud-native applications16:46 Infrastructure as code and security visibility22:08 Least privilege and cloud configuration24:12 Helping developers take on new responsibilities27:27 AppSec practices in a cloud-native world29:31 Prioritizing vulnerabilities beyond severity31:49 Giving developers the tools to help themselves33:08 Building safer Node.js container images37:10 Differences between development and production38:40 Practical takeaways and a threat modeling mindset
Embed this episode
What this episode covers
Cloud-native development gives engineers control over more of the stack, but it also gives them more security decisions to get wrong. Liran Tal, an open-source contributor and developer advocate, joins Chris and Robert to explore that expanding responsibility. They define cloud-native applications, examine containers and infrastructure as code, and discuss how security ownership changes when developers choose runtimes, dependencies, and deployment configurations. Liran explains why vulnerabil...
Ready to play
Liran Tal — Cloud native application security, what’s a developer to do?
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.